Effective 9 September 2026 · Physique is made by Sync LC, Grand Rapids, Michigan · info@syncgr.com
Physique is a daily log for food, workouts and weigh-ins. This page says what the app collects, why, where it lives, and how to get rid of it. It is written to be read, not skimmed past.
What we collect
Account: your email address and a password (stored hashed by Amazon Cognito). A display name if you add one.
What you log: food items and notes, workouts, weigh-ins, saved foods and recipes, and any macro or nutrient numbers you enter or accept.
Photos: food photos you choose to take or upload. We do not read the GPS location from photos, and the app never accesses your camera or gallery except when you tap the camera button.
Assistant messages: the text you type to the in-app assistant and its replies, kept with the day they belong to.
Usage counters: how many assistant tokens your account has used this month, to enforce the plan allowance.
We do not collect location, contacts, advertising identifiers, or analytics about how you use the app. There are no ads and no ad SDKs.
How it is used
To show you your own log, totals and history.
To run the assistant: your message, the day you are looking at, your saved foods, and (if you attach one) a food photo are sent to a language model running in our own AWS account (Amazon Bedrock). The model's output is applied to your draft; nothing is written until you press Save.
When you ask about a food we don't have, the assistant may search the web for nutrition figures. Only the food name is sent to the search service, never your identity or your log. Web-sourced numbers are always marked as estimates.
To send you account emails: sign-up confirmation and password reset. Nothing else.
Who sees it
Nobody but you. Your data is stored in Sync LC's own AWS account (US East), in per-user partitions, with photos in a private bucket served only through short-lived signed links. We do not sell data, share it with advertisers, or use it to train models. Our service providers are Amazon Web Services (hosting, storage, authentication, model inference) and, if you use web lookups, the search provider named in the reply. If we ever add paid plans, payments would be handled by Stripe and we would never see your card number.
Agent access
You can create revocable credentials so your own tools (for example an AI agent you run) can read or write your log through our API. Those credentials are read-only unless you choose otherwise, expire, and can be revoked in the app at any time. We never issue them on your behalf.
Keeping and deleting it
Your log is kept as long as your account exists.
Export everything as JSON from the account panel or the API at any time.
Delete your account from the account panel, or email info@syncgr.com from your account address. Deletion removes your account, log, photos, saved foods, assistant history and credentials within 30 days; backups age out within 35 days after that.
Children
Physique is for adults. We do not knowingly accept accounts from anyone under 18. If you believe a child has created one, email us and we will delete it.
Security
Traffic is encrypted in transit (TLS). Passwords are never stored in plain text. Access to production data is limited to the people who run the service, and the app never carries long-lived cloud credentials.
Changes
If this policy changes in a way that matters, the date at the top moves and the app tells you on next sign-in. Questions: info@syncgr.com.